Skip to content

fix: Correct test cases and audit commands for rh-1.8, cis-1.11, gke-1.8.0, and eks-1.7.0 benchmarks#1988

Open
amitk1sharma wants to merge 1 commit intoaquasecurity:mainfrom
VoerEirAB:fix/ocp-permissions
Open

fix: Correct test cases and audit commands for rh-1.8, cis-1.11, gke-1.8.0, and eks-1.7.0 benchmarks#1988
amitk1sharma wants to merge 1 commit intoaquasecurity:mainfrom
VoerEirAB:fix/ocp-permissions

Conversation

@amitk1sharma
Copy link
Copy Markdown

@amitk1sharma amitk1sharma commented Oct 29, 2025

This PR fixes several test case inconsistencies and incorrect audit commands in the benchmark YAML files for:

rh-1.8
cis-1.11
gke-1.8.0
eks-1.7.0

Changes made:

Fixed incorrect test case names and descriptions
Updated audit commands
Adjusted scored values to align with CIS standards
Improved remediation steps for clarity
Verified validation paths for OCP, GKE, and EKS consistency

Associated Issue: Fixes #1993

Comment thread cfg/cis-1.11/master.yaml Outdated
Comment thread cfg/cis-1.11/node.yaml
Comment thread cfg/eks-1.7.0/controlplane.yaml
Comment thread cfg/eks-1.7.0/controlplane.yaml Outdated
Comment thread cfg/eks-1.7.0/node.yaml
Comment thread cfg/eks-1.7.0/policies.yaml Outdated
Comment thread cfg/eks-1.7.0/policies.yaml Outdated
Comment thread cfg/eks-1.7.0/policies.yaml Outdated
Comment thread cfg/eks-1.7.0/policies.yaml Outdated
Comment thread cfg/eks-1.7.0/policies.yaml Outdated
Comment thread cfg/gke-1.8.0/managedservices.yaml
Comment thread cfg/rh-1.8/node.yaml
Comment thread cfg/rh-1.8/node.yaml Outdated
Comment thread cfg/rh-1.8/policies.yaml Outdated
Comment thread cfg/rh-1.8/master.yaml
Comment thread cfg/rh-1.8/master.yaml Outdated
Comment thread cfg/rh-1.8/master.yaml Outdated
@amitk1sharma amitk1sharma changed the title Enhance kube-bench configurations fix: Correct test cases and audit commands for rh-1.8, cis-1.11, gke-1.8.0, and eks-1.7.0 benchmarks Nov 6, 2025
@amitk1sharma
Copy link
Copy Markdown
Author

Hi @afdesk @mozillazg , Could you please review this PR when you get a chance?
This PR addresses Issue #1993. Thank you!

Comment thread cfg/rh-1.8/node.yaml
Comment thread cfg/eks-1.7.0/policies.yaml
Comment thread cfg/rh-1.8/master.yaml Outdated
Comment thread cfg/rh-1.8/node.yaml Outdated
Comment thread cfg/rh-1.8/policies.yaml Outdated
@afdesk
Copy link
Copy Markdown
Collaborator

afdesk commented Nov 27, 2025

@amitk1sharma thanks a lot for your efforts!
I left some comments, could you pls clarify it?
thank you for the PR!!

@afdesk
Copy link
Copy Markdown
Collaborator

afdesk commented Nov 27, 2025

@mozillazg @LaibaBareera Could you pls take a look at this great job too?

Copy link
Copy Markdown
Contributor

@mozillazg mozillazg left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@amitk1sharma Thanks for your contribution! I don't have more comments. Please check the comments from @afdesk when you get a chance. Thanks!

Comment thread cfg/cis-1.11/etcd.yaml Outdated
Comment thread cfg/gke-1.8.0/node.yaml
Comment thread cfg/eks-1.7.0/policies.yaml
Comment thread cfg/cis-1.11/controlplane.yaml Outdated
Comment thread cfg/cis-1.11/etcd.yaml Outdated
Comment thread cfg/cis-1.11/etcd.yaml Outdated
Comment thread cfg/cis-1.11/etcd.yaml Outdated
Comment thread cfg/cis-1.11/master.yaml Outdated
Comment thread cfg/cis-1.11/node.yaml Outdated
Comment thread cfg/cis-1.11/policies.yaml Outdated
@amitk1sharma
Copy link
Copy Markdown
Author

Hi @afdesk @mozillazg, I have resolved the previous comments.
Kindly review the PR again when you get a chance.

@amitk1sharma
Copy link
Copy Markdown
Author

Hi @afdesk @mozillazg,
I’ve addressed all the previous review comments.
Could you please merge this when you get a chance?

Copy link
Copy Markdown
Contributor

@mozillazg mozillazg left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, Thanks for your contribution!

Copy link
Copy Markdown
Contributor

@andypitcher andypitcher left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving the CIS-1.11 part, thanks !

@LaibaBareera
Copy link
Copy Markdown
Collaborator

@amitk1sharma LGTM too.

@afdesk
Copy link
Copy Markdown
Collaborator

afdesk commented Feb 12, 2026

@amitk1sharma could you pls rebase this branch with the main?
I can't merge it for a while
thanks

@amitk1sharma amitk1sharma force-pushed the fix/ocp-permissions branch 2 times, most recently from f394f56 to f5a3aba Compare February 12, 2026 06:59
@amitk1sharma
Copy link
Copy Markdown
Author

amitk1sharma commented Feb 12, 2026

@afdesk Rebase Done.
Could you please merge now?

Comment thread cfg/rh-1.8/node.yaml Outdated
Comment thread cfg/rh-1.8/policies.yaml Outdated
Comment thread cfg/rh-1.8/etcd.yaml Outdated
Comment thread cfg/rh-1.8/master.yaml Outdated
Comment thread cfg/rh-1.8/master.yaml Outdated
Comment thread cfg/gke-1.8.0/managedservices.yaml Outdated
@afdesk
Copy link
Copy Markdown
Collaborator

afdesk commented Feb 13, 2026

@afdesk Rebase Done. Could you please merge now?

@amitk1sharma thanks for your efforts.
there were made a lot of changes, so I had to re-review this PR again, and left some marks.

Could you pls take a look at them and update?

I realize that some notes weren't made in your PR, but these typos should be fixed too to improve the project.
Thanks a lot!

@amitk1sharma amitk1sharma force-pushed the fix/ocp-permissions branch 2 times, most recently from c9b67f9 to 8cad908 Compare February 24, 2026 04:24
@amitk1sharma
Copy link
Copy Markdown
Author

Hi @afdesk @mozillazg @andypitcher ,

I’ve addressed all the previous review comments and updated the PR accordingly.
Could you please take another look when you have a chance?

Thank you!

@afdesk
Copy link
Copy Markdown
Collaborator

afdesk commented Feb 24, 2026

@amitk1sharma thank you so much for your efforts!
i'll re-review ASAP

Comment thread cfg/rh-1.8/policies.yaml Outdated
@afdesk
Copy link
Copy Markdown
Collaborator

afdesk commented Feb 25, 2026

@amitk1sharma thanks for your efforts!
I found an issue with one check.
could you pls take a look?

@amitk1sharma
Copy link
Copy Markdown
Author

amitk1sharma commented Mar 17, 2026

Hi @afdesk @mozillazg @andypitcher,

Just a gentle follow-up on this PR.
Please let me know if any further changes are required from my side.
If everything looks good, could you please merge it when you have a chance?

Thanks!

sync cfg updates

sync cfg updates with upstream

Resolve PR comments

comments resolve

PR comments resolved

Removed extra space

Correct spacing and indentation issues

Resolved PR comments

Resolve PR comments
@amitk1sharma
Copy link
Copy Markdown
Author

Hi @afdesk @mozillazg @andypitcher ,

Just a gentle reminder regarding this PR. It has been open for a couple of weeks now.
Could you please take a look when you have some time and let me know if any changes are needed from my side?

Thanks in advance!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix incorrect audit commands, test names, and scored values for rh-1.8, cis-1.11, gke-1.8.0, and eks-1.7.0 benchmarks.

6 participants